Italy Italy

Intesa Sanpaolo Vita S.p.a.

20,000 €

GDPR enforcement action by Italian Data Protection Authority (Garante) on 2022-07-07.

Rank · Sector
#161
of 322 in Finance, Insurance and Consulting
Rank · Italy
#194
of 543
Rank · All fines
#1,055
of 3,042

Case details

Authority
Italian Data Protection Authority (Garante)
Date
2022-07-07
Controller / Processor
Intesa Sanpaolo Vita S.p.a.
Sector
Finance, Insurance and Consulting
Quoted Articles
Art. 5 (1) a), f) GDPR
Type of violation
Non-compliance with general data processing principles

Summary

The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the DPA against the controller for the unauthorized disclosure of their personal data. In the course of its investigation, the DPA found that the controller had disclosed personal data, such as first name, last name and information about the policy, to third parties without authorization. The unauthorized disclosure had occurred due to an employee's error.

Open original source Links to the regulator's original publication or another source.

Related fines